Network attack identification method based on Snd-LSTM network model
Through the network attack identification method based on the Snd-LSTM network model, the problem of delay and difficulty in targeted processing of network attack identification in the prior art is solved, real-time and accurate network attack detection and early warning are realized, and network security response capabilities are improved.
Patent Information
- Application Number
- CN202510250653.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-03-04
AI Technical Summary
The prior art is difficult to detect and early warning of network attacks in real time in high-speed network traffic, resulting in delays in identifying early warnings and difficult to implement targeted processing according to the type of attack.
The network attack identification method based on the Snd-LSTM network model is adopted. By real-time acquisition and preprocessing of network traffic data, the Snd-LSTM network model is designed to capture timing characteristics and long-term dependencies, the model is trained to analyze the dynamic changes of network traffic, and probability vectors of different attack types are output, combined with the early warning threshold to trigger the early warning mechanism and take corresponding processing.
It realizes rapid response to potential threats in a real-time environment, improves the accuracy and efficiency of attack detection, and can accurately warning different levels of attack events and take corresponding measures.
Smart Images

Figure CN120034389A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network models, and in particular to a network attack identification method based on a Snd-LSTM network model. Background Art
[0002] With the popularization of the Internet and the development of information technology, network attacks are becoming increasingly diverse and complex. For example, DDoS attacks, SQL injections, malware, phishing attacks, data leaks, etc. have become common network security threats. Each attack has different characteristics and intrusion methods. In recent years, deep learning (especially LSTM) has gradually become an important technology in the field of network attack identification due to its powerful capabilities in time series data modeling and pattern recognition. LSTM networks perform well in processing time series information such as network traffic data, intrusion logs, and protocol data. They can capture long-term dependencies in time and identify potential attack behaviors.
[0003] In the prior art, it is difficult to detect and warn of network attacks in real time in high-speed network traffic for real-time traffic analysis in a network environment, resulting in a certain delay in the identification and warning of network attacks, and it is difficult to implement corresponding processing methods in a targeted manner according to the type of network attack. Therefore, a network attack identification method based on the Snd-LSTM network model is proposed to solve the above problems. Summary of the invention
[0004] The purpose of the present invention is to provide a network attack identification method based on the Snd-LSTM network model to solve the problems raised in the above background technology.
[0005] In order to solve the above technical problems, the technical solution adopted by the present invention is:
[0006] A network attack identification method based on the Snd-LSTM network model includes the following steps:
[0007] Step 1: Collect network traffic data in real time and pre-process the network traffic data using a data cleaning algorithm;
[0008] Step 2: Design the structure of the Snd-LSTM network model to capture the timing characteristics of network traffic and model long-term dependencies;
[0009] Step 3: Use the preprocessed network traffic data to train the Snd-LSTM network model, and continuously adjust the model parameters through the back propagation algorithm to minimize the loss function, and then analyze the dynamic change trend of network traffic;
[0010] Step 4: Input the network traffic data to be detected into the trained Snd-LSTM model, perform inference calculation based on the network traffic feature pattern, and output a probability vector representing the probability of different network attack types;
[0011] Step 5: Preset the warning threshold, and combine the output results of the Snd-LSTM model to determine whether the maximum probability category output by the model exceeds the preset warning threshold. If it exceeds, it is determined as the corresponding network attack type and triggers the warning mechanism. Otherwise, it is regarded as normal traffic.
[0012] Step 6. Take appropriate measures according to the risk level of the warning, implement automatic blocking, traffic diversion and other measures to deal with confirmed attack events, and after the attack event, conduct a detailed analysis of the data of the entire attack process to form an attack report, which provides a basis for optimizing network security strategies and improving the Snd-LSTM model.
[0013] A further improvement of the technical solution of the present invention is that in step 1, the process of network flow data collection and preprocessing is:
[0014] Determine the network area to be monitored based on the needs, including but not limited to specific subnets, servers, routers, etc., and use the network packet capture tool Wireshark to select the corresponding network interface for monitoring and capture the network traffic data of the network area;
[0015] Temporarily store the captured network traffic data in a specified directory on the local disk in the file format of PCAP (PacketCapture), and use the Wireshark command line tool tshark to parse the PCAP file to extract high-level protocol information. Then extract key fields including source IP address, destination IP address, timestamp, and packet size from the parsed data, and save the extracted data in CSV format for subsequent analysis.
[0016] Preprocess the parsed network traffic data, including data cleaning and data normalization.
[0017] A further improvement of the technical solution of the present invention is that in step 2, the process of designing the Snd-LSTM network model structure is:
[0018] Sorting the preprocessed network traffic data in chronological order and creating a sliding window to generate time series data, wherein the size of the sliding window is determined according to the characteristics of the network traffic and the analysis requirements;
[0019] Design the structure of the Snd-LSTM network model, including the input layer, LSTM layer, fully connected layer, and output layer;
[0020] Among them, the input layer: accepts the preprocessed time series data as input. The shape of the input data is the number of samples, the number of time steps, and the number of features. By adjusting the number of LSTM layers, the number of units in each LSTM layer, as well as using optimization algorithms and learning rate scheduling strategies, the model's ability to model long-term dependencies can be improved;
[0021] LSTM layer: uses multiple LSTM units to capture temporal features. Calculate the number of LSTM layer units. The number of units in each LSTM layer (i.e., the number of hidden units) is determined according to data complexity and computing resources, and dropout regularization is used to calculate the dropout regularization rate to prevent overfitting;
[0022] Fully connected layer: After the LSTM layer, one or more fully connected layers need to be added for feature combination and decision-making;
[0023] Output layer: Select the corresponding output layer according to the task type, which is used to classify different attack types. For binary classification tasks (normal / abnormal), the output layer has one neuron and uses the sigmoid activation function. For multi-classification tasks, there are multiple neurons corresponding to different types of attacks and use the softmax activation function.
[0024] A further improvement of the technical solution of the present invention lies in: the calculation expression of the sliding window size is:
[0025]
[0026] In the formula, W is the sliding window size, which is the number of time steps. N is the total number of samples in the dataset, representing the overall scale of the data. σ is the standard deviation of the data noise, which can be obtained by calculating the change amount at each time point in the dataset;
[0027] The calculation expression of the number of LSTM layer units is:
[0028]
[0029] In the formula, H is the number of units in each LSTM layer. C is a measure of data complexity, which can be obtained by calculating the entropy between different features in the dataset. K is the limitation of computing resources, based on the GPU memory size or CPU computing power. α is a tuning parameter used to control the rate of change of the number of units with complexity and resource limitations;
[0030] The calculation expression of the dropout regularization rate is:
[0031]
[0032] Where D is the dropout regularization rate, which represents the ratio of dropout regularization, M is the number of samples in the data set, and β is a tuning parameter used to control the rate at which the dropout ratio changes with the size of the data set.
[0033] A further improvement of the technical solution of the present invention is that in step 3, the training process of the Snd-LSTM network model is:
[0034] Ensure that the network traffic data has been sorted in chronological order and generate sliding window time series data, and divide the data set into training set, validation set and test set, with a division ratio of 70% training set, 15% validation set and 15% test set. The training set is used to train the model, the validation set is used to adjust the model parameters and select the best model, and the test set is used to evaluate the performance of the model;
[0035] Assign a label of the corresponding specific attack type to each sample according to the multi-classification task type, and compile the model. Model compilation includes selecting the loss function, selecting the optimizer, and configuring the evaluation index. For the multi-classification task type, use categorical_crossentropy, select the Adam optimizer by default, and configure the evaluation index including accuracy, recall, F1 score, etc.
[0036] Input the training set data into the Snd-LSTM network model, calculate the value of the loss function through forward propagation, calculate the gradient through the back-propagation algorithm, and use the optimization algorithm to update the model parameters. Repeat this process until the value of the loss function reaches the preset number of iterations. Evaluate the performance of the model on the validation set, adjust the model parameters (the number of LSTM layers, the number of units, the dropout regularization rate, etc.) according to the validation results, retrain the model, evaluate the performance of the final model on the test set, and calculate evaluation indicators such as accuracy, recall, and F1 score.
[0037] The trained Snd-LSTM network model is used to predict and analyze network traffic data and identify the dynamic change trend of abnormal behavior of network traffic.
[0038] A further improvement of the technical solution of the present invention is that the calculation expression of the dynamic change trend of the abnormal behavior is:
[0039]
[0040] Where A(t) is the quantitative value of the dynamic change trend of abnormal behavior at time t, and F iis the network flow value at time i, μ is the average of recent flow values, which is the mean within a sliding window, W is the sliding window size, thr is the preset abnormal behavior threshold used to detect the significance of flow changes, k is an adjustment parameter used to control the decay rate of abnormal values over time, ΔF(t) is the difference between the flow value at time t and the flow value at the previous moment, and A(t) ranges from 0 to 1. When the flow change is very significant and continuous, A(t) approaches 1, and when the flow change is not significant or is within the normal range, A(t) approaches 0.
[0041] A further improvement of the technical solution of the present invention is that in step 4, the output process of the probability vector is:
[0042] Collect real-time network traffic data from the network monitoring system and extract features including packet size, packet arrival interval, protocol type, source / destination IP address and port number;
[0043] Load the trained Snd-LSTM model, make the loaded model compatible with the feature set extracted from real-time network traffic data, and input the preprocessed network traffic data into the model in batches;
[0044] The forward propagation calculation is performed through the Snd-LSTM model. The Snd-LSTM model gradually calculates the hidden state based on the input features and the learned weights, and finally outputs a probability vector. Each element in the probability vector corresponds to a specific attack type.
[0045] A further improvement of the technical solution of the present invention is that the calculation expression of the probability vector is:
[0046]
[0047] z j =min(θ·ReLU(W j ·h T +b j ), δ);
[0048] Where P j is the probability vector of the j-th attack, z j is the linear combination value before the fully connected layer and activation function, τ is the smoothing parameter, and h T is the hidden state vector of the LSTM unit at time step T, W j and b j are the weight matrix and bias vector of the fully connected layer, respectively, and θ is the scaling factor used to adjust z j The dynamic range of δ is the upper limit value, which is used to prevent z j Too big, each P jThe value range is [0,1], and all P j The sum of is 1.
[0049] A further improvement of the technical solution of the present invention is that in step 5, the triggering process of the early warning mechanism is:
[0050] According to the network attack warning requirements, combined with historical data, business requirements and security policies, the risk level of network attack types is analyzed and divided into low-risk attacks, medium-risk attacks and high-risk attacks. Different warning thresholds are set for each type of network attack. Normal traffic does not trigger warnings and there is no need to set warning thresholds. The warning threshold for low-risk attacks is 0.7, the warning threshold for medium-risk attacks is 0.85, and the warning threshold for high-risk attacks is 0.95.
[0051] Find the maximum probability value from the output probability vector and compare it with the warning threshold to determine whether the maximum probability value exceeds the preset warning threshold;
[0052] If the maximum probability value does not exceed the warning threshold, it is regarded as normal traffic and no warning operation is performed. If the maximum probability value exceeds the warning threshold, it is determined to be a network attack and matched with the corresponding network attack type, thereby triggering the warning mechanism, which includes sending alarms, recording logs and blocking connections.
[0053] A further improvement of the technical solution of the present invention is that in step 6, the process of forming the attack report is as follows:
[0054] According to the output probability of the Snd-LSTM model and the preset warning threshold, the risk level of the attack event is determined, and corresponding emergency response measures are implemented according to the risk level. For high-risk network attack events, the automatic blocking mechanism is immediately activated to cut off the connection between the attack source and the system to prevent the attack from spreading. For medium-risk network attack events, the attacked traffic is diverted to the backup system or sandbox environment for analysis and processing to reduce the pressure on the main system and collect more attack information. For all risk network attack events, real-time monitoring and log recording are required for subsequent analysis and tracking;
[0055] After blocking the attack source, isolate the affected system components and start the recovery process to ensure that the business resumes normal operation as soon as possible. According to the attack type and means, strengthen the system security, repair vulnerabilities, and improve defense capabilities;
[0056] After the attack is over, collect and analyze data from the entire attack process, including attack sources, attack methods, attack paths, and system responses. Based on the results of the attack data analysis, write a detailed attack report, including an overview of the attack, impact analysis, emergency response measures, security reinforcement recommendations, and future defense strategies. Then, based on the recommendations in the attack report, optimize network security strategies, including updating firewall rules, strengthening the configuration of intrusion detection systems (IDS) and intrusion prevention systems (IPS), and improve the Snd-LSTM model, including adjusting model parameters, increasing the diversity of training data, introducing new features, etc., to improve the model's ability to detect new types of attacks.
[0057] Due to the adoption of the above technical solution, the present invention has the following technical advances compared with the prior art:
[0058] 1. The present invention provides a network attack identification method based on the Snd-LSTM network model. The Snd-LSTM model can capture the time dependency and long-distance correlation in network traffic data through its sequence processing capability, and can effectively distinguish normal traffic from abnormal attack traffic by learning patterns in historical data using Snd-LSTM, which not only improves the accuracy of attack detection, but also significantly improves the detection efficiency, so that the system can quickly respond to potential threats in a real-time environment.
[0059] 2. The present invention provides a network attack identification method based on the Snd-LSTM network model. Combined with the output probability of the Snd-LSTM model and the preset warning threshold, it can realize accurate warning of attack events of different levels, which not only improves the sensitivity and accuracy of the warning, but also enables the system to adopt different levels of response strategies according to the nature and severity of the attack. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0061] Figure 1 It is a schematic diagram of the process of the present invention;
[0062] Figure 2 Schematic diagram of the output flow of the probability vector of the present invention. DETAILED DESCRIPTION
[0063] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0064] Embodiment 1, as Figure 1 As shown, the present invention provides a network attack identification method based on the Snd-LSTM network model, comprising the following steps:
[0065] Step 1: Collect network traffic data in real time, and use data cleaning algorithms to pre-process the network traffic data. Determine the network area to be monitored according to the needs, including but not limited to specific subnets, servers, routers, etc., and use the network packet capture tool Wireshark to select the corresponding network interface for monitoring, capture the network traffic data of the network area, and temporarily store the captured network traffic data in the specified directory of the local disk. The file format is PCAP (Packet Capture), and use the Wireshark command line tool tshark to parse the PCAP file, extract the high-level protocol information, and then extract the key fields including source IP address, destination IP address, timestamp and data packet size from the parsed data, and save the extracted data in CSV format to prepare for subsequent analysis. Pre-process the parsed network traffic data, including data cleaning and data normalization. Among them, analyze the network traffic data, identify and delete unnecessary or duplicate information to simplify the data set and improve the efficiency of subsequent processing. For data entries with missing values, use mean filling or interpolation to fill them, normalize the features of the network traffic data, convert data of different scales to the same range, and ensure that the data values of different features are at the same level so that the model can learn and recognize better;
[0066] Step 2: Design the structure of the Snd-LSTM network model, capture the timing characteristics in the network traffic, and model the long-term dependencies. Sort the preprocessed network traffic data in chronological order, and create a sliding window to generate time series data. The size of the sliding window is determined according to the characteristics of the network traffic and the analysis requirements. Design the structure of the Snd-LSTM network model, including the input layer, LSTM layer, fully connected layer, and output layer.
[0067] Among them, input layer: accepts preprocessed time series data as input. The shape of input data is the number of samples, time steps, and number of features. The model's ability to model long-term dependencies can be improved by adjusting the number of LSTM layers and the number of units in each LSTM layer, as well as using optimization algorithms and learning rate scheduling strategies. LSTM layer: uses multi-layer LSTM units to capture time series features, calculates the number of LSTM layer units, and the number of LSTM units in each layer (i.e., the number of hidden units) is determined according to data complexity and computing resources, and uses dropout regularization to calculate the dropout regularization rate to prevent overfitting. Fully connected layer: After the LSTM layer, one or more fully connected layers need to be added for feature combination and decision-making. Output layer: Select the corresponding output layer according to the task type to classify different types of attacks. For binary classification tasks (normal / abnormal), the output layer has one neuron and uses the sigmoid activation function. For multi-classification tasks, there are multiple neurons corresponding to different types of attacks and use the softmax activation function.
[0068] Furthermore, the calculation expression of the sliding window size is:
[0069]
[0070] In the formula, W is the sliding window size, that is, the time step, N is the total number of samples in the data set, representing the overall scale of the data, and σ is the standard deviation of the data noise, which can be obtained by calculating the change in each time point in the data set. When the total number of samples N in the data set increases, the sliding window size W tends to increase to capture more time series information. When the standard deviation σ of the data noise increases, the sliding window size N tends to decrease to reduce the impact of noise on the model.
[0071] The calculation expression for the number of LSTM layer units is:
[0072]
[0073] Where H is the number of units in each LSTM layer, C is a measure of data complexity, which can be obtained by calculating the entropy between different features in the data set, K is the limitation of computing resources, based on the memory size of the GPU or the computing power of the CPU, and α is a tuning parameter used to control the rate at which the number of units changes with complexity and resource limitations. When the data complexity increases, the number of LSTM layer units tends to increase to capture more time series features. When the computing resource limit decreases, the number of LSTM layer units tends to decrease to adapt to limited computing resources.
[0074] The calculation expression of the dropout regularization rate is:
[0075]
[0076] Where D is the dropout regularization rate, which represents the ratio of dropout regularization, M is the number of samples in the data set, and β is a tuning parameter used to control the rate at which the dropout ratio changes with the size of the data set. When the number of samples in the data set increases, the dropout ratio tends to decrease because more data helps reduce the risk of overfitting. The value of β affects the sensitivity of D to changes in M. A larger β value will result in a higher dropout ratio, while a smaller β value will result in a lower dropout ratio.
[0077] Step 3: Use the preprocessed network traffic data to train the Snd-LSTM network model, and continuously adjust the model parameters through the back propagation algorithm to minimize the loss function, and then analyze the dynamic change trend of the network traffic, ensure that the network traffic data has been sorted in chronological order and generate the time series data of the sliding window, and divide the data set into training set, validation set and test set, with a division ratio of 70% training set, 15% validation set, and 15% test set. The training set is used to train the model, the validation set is used to adjust the model parameters and select the best model, and the test set is used to evaluate the performance of the model. According to the multi-classification task type, each sample is assigned a label of the corresponding specific attack type, and the model is compiled. The model compilation includes selecting the loss function, selecting the optimizer, and configuring the evaluation index. For the multi-classification task type, use categoric al_crossentropy, Adam optimizer is selected by default, and evaluation indicators such as accuracy, recall, and F1 score are configured. The training set data is input into the Snd-LSTM network model, the value of the loss function is calculated through forward propagation, the gradient is calculated through the back-propagation algorithm, and the model parameters are updated using the optimization algorithm. This process is repeated until the value of the loss function reaches the preset number of iterations. The performance of the model is evaluated on the validation set, and the model parameters (the number of LSTM layers, the number of units, the dropout regularization rate, etc.) are adjusted according to the validation results. The model is retrained, and the performance of the final model is evaluated on the test set. Evaluation indicators such as accuracy, recall, and F1 score are calculated. The trained Snd-LSTM network model is used to predict and analyze network traffic data to identify the dynamic change trend of abnormal behavior of network traffic.
[0078] Furthermore, the calculation expression of the dynamic change trend of abnormal behavior is:
[0079]
[0080] Where A(t) is the quantitative value of the dynamic change trend of abnormal behavior at time t, and F iis the network traffic value at time i, μ is the average of recent traffic values, which is the mean within a sliding window, W is the size of the sliding window, thr is the preset abnormal behavior threshold used to detect the significance of traffic changes, k is an adjustment parameter used to control the decay rate of abnormal values over time, ΔF(t) is the difference between the traffic value at time t and the traffic value at the previous moment, and A(t) ranges from 0 to 1. When the traffic change is very significant and continuous, A(t) approaches 1, and when the traffic change is not significant or is within the normal range, A(t) approaches 0;
[0081] Step 4: Input the network traffic data to be detected into the trained Snd-LSTM model, perform inference calculation based on the network traffic feature pattern, and output a probability vector representing the probability of different network attack types;
[0082] Step 5: Preset the warning threshold, and combine the output results of the Snd-LSTM model to determine whether the maximum probability category output by the model exceeds the preset warning threshold. If it exceeds, it is determined as the corresponding network attack type and triggers the warning mechanism. Otherwise, it is regarded as normal traffic.
[0083] Step 6. Take appropriate measures according to the risk level of the warning, implement automatic blocking, traffic diversion and other measures to deal with confirmed attack events, and after the attack event, conduct a detailed analysis of the data of the entire attack process to form an attack report, which provides a basis for optimizing network security strategies and improving the Snd-LSTM model.
[0084] Embodiment 2, as Figure 2 As shown, based on Example 1, the present invention provides a technical solution: Preferably, in step 4, the output process of the probability vector is:
[0085] Collect real-time network traffic data from the network monitoring system, and extract features including packet size, packet arrival interval, protocol type, source / destination IP address and port number from it. Load the trained Snd-LSTM model to make the loaded model compatible with the feature set extracted from the real-time network traffic data. Input the preprocessed network traffic data into the model in batches, and perform forward propagation calculation through the Snd-LSTM model. The Snd-LSTM model gradually calculates the hidden state based on the input features and the learned weights, and finally outputs a probability vector. Each element in the probability vector corresponds to a specific attack type.
[0086] Furthermore, the calculation expression of the probability vector is:
[0087]
[0088] z j =min(θ·ReLU(Wj ·h T +b j ), δ);
[0089] Where P j is the probability vector of the j-th attack, z j is the linear combination value before the fully connected layer and activation function, τ is the smoothing parameter, and h T is the hidden state vector of the LSTM unit at time step T, W j and b j are the weight matrix and bias vector of the fully connected layer, respectively, and θ is the scaling factor used to adjust z j The dynamic range of δ is the upper limit, which is used to prevent z j Too big, each P j The value range is [0,1], and all P j The sum of is 1, when z j When P is larger, j The value of will increase significantly; when z j When P is small, j The value of will approach 0. By adjusting the values of τ, θ and δ, the distinction between different categories can be controlled;
[0090] In step 5, the triggering process of the early warning mechanism is:
[0091] According to the network attack warning requirements, combined with historical data, business requirements and security policies, the risk level of network attack types is analyzed and divided into low-risk attacks, medium-risk attacks and high-risk attacks. Different warning thresholds are set for each type of network attack. Normal traffic does not trigger warnings and there is no need to set warning thresholds. The warning threshold for low-risk attacks is 0.7, the warning threshold for medium-risk attacks is 0.85, and the warning threshold for high-risk attacks is 0.95. The maximum probability value is found from the output probability vector and compared with the warning threshold to determine whether the maximum probability value exceeds the preset warning threshold. If the maximum probability value does not exceed the warning threshold, it is regarded as normal traffic and no warning operation is performed. If the maximum probability value exceeds the warning threshold, it is determined to be a network attack and matched with the corresponding network attack type, thereby triggering the warning mechanism. The warning mechanism includes sending alarms, recording logs and blocking connections. Alarms are sent to relevant personnel through emails, text messages or system notifications, and the detected attack events are recorded in detail in log files for subsequent analysis and auditing. For high-risk attack types, measures are taken immediately to block related connections to prevent further harm.
[0092] In step 6, the attack report is generated as follows:
[0093] According to the output probability of the Snd-LSTM model and the preset warning threshold, the risk level of the attack event is determined, and corresponding emergency response measures are implemented according to the risk level. For high-risk network attack events, the automatic blocking mechanism is immediately activated to cut off the connection between the attack source and the system to prevent the attack from spreading. For medium-risk network attack events, the attacked traffic is diverted to the backup system or sandbox environment for analysis and processing to reduce the pressure on the main system and collect more attack information. For all risk network attack events, real-time monitoring and log recording are required for subsequent analysis and tracking. After blocking the attack source, the affected system components are isolated and the recovery process is initiated to ensure that the business resumes normal operation as soon as possible and the root cause is resolved. According to the attack type and means, the system is reinforced, vulnerabilities are repaired, and defense capabilities are improved. After the attack incident is over, data on the entire attack process is collected and analyzed, including the attack source, attack means, attack path, and system response. Based on the results of the attack data analysis, a detailed attack report is written, including an overview of the attack, impact analysis, emergency response measures, security reinforcement suggestions, and future defense strategies. Then, based on the suggestions in the attack report, the network security strategy is optimized, including updating firewall rules, strengthening the configuration of intrusion detection systems (IDS) and intrusion prevention systems (IPS), etc. The Snd-LSTM model is improved, including adjusting model parameters, increasing the diversity of training data, introducing new features, etc., to improve the model's detection capabilities for new attacks.
[0094] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A network attack identification method based on the Snd-LSTM network model, characterized in that: The following steps are involved: Step 1: Collect network traffic data in real time and pre-process the network traffic data using a data cleaning algorithm; Step 2: Design the structure of the Snd-LSTM network model to capture the timing characteristics of network traffic; Step 3: Use the preprocessed network traffic data to train the Snd-LSTM network model, and then analyze the dynamic change trend of network traffic; Step 4: Input the network traffic data to be detected into the trained Snd-LSTM model, perform inference calculation based on the network traffic feature pattern, and output a probability vector representing the probability of different network attack types; Step 5: Preset the warning threshold, and combine the output results of the Snd-LSTM model to determine whether the maximum probability category output by the model exceeds the preset warning threshold. If it exceeds, it is determined as the corresponding network attack type and triggers the warning mechanism. Otherwise, it is regarded as normal traffic. Step 6: Take appropriate measures according to the risk level of the warning, and after the attack is over, analyze the data of the entire attack process to form an attack report.
2. According to a network attack identification method based on the Snd-LSTM network model according to claim 1, it is characterized in that: In step 1, the process of network traffic data collection and preprocessing is as follows: Determine the network area to be monitored based on the needs, and use the network packet capture tool Wireshark to select the corresponding network interface for monitoring and capture the network traffic data of the network area; Temporarily store the captured network traffic data in a specified directory on the local disk in the PCAP file format, and use the Wireshark command line tool tshark to parse the PCAP file to extract high-level protocol information. Then, extract key fields including source IP address, destination IP address, timestamp, and packet size from the parsed data, and save the extracted data in CSV format. Preprocess the parsed network traffic data, including data cleaning and data normalization.
3. According to a network attack identification method based on the Snd-LSTM network model according to claim 2, it is characterized in that: In step 2, the process of designing the Snd-LSTM network model structure is: Sorting the preprocessed network traffic data in chronological order and creating a sliding window to generate time series data, wherein the size of the sliding window is determined according to the characteristics of the network traffic and the analysis requirements; Design the structure of the Snd-LSTM network model, including the input layer, LSTM layer, fully connected layer, and output layer; Among them, the input layer: accepts the preprocessed time series data as input, and the shape of the input data is the number of samples, time steps, and number of features; LSTM layer: Use multiple layers of LSTM units to capture time series features, calculate the number of LSTM layer units, and use dropout regularization to calculate the dropout regularization rate to prevent overfitting; Fully connected layer: After the LSTM layer, one or more fully connected layers need to be added for feature combination and decision making; Output layer: Select the corresponding output layer according to the task type to classify different attack types. For binary classification tasks, the output layer has one neuron and uses the sigmoid activation function. For multi-classification tasks, there are multiple neurons corresponding to different types of attacks and use the softmax activation function.
4. According to claim 3, a network attack identification method based on the Snd-LSTM network model is characterized in that: The calculation expression of the sliding window size is: Where W is the sliding window size, that is, the time step, N is the total number of samples in the data set, and σ is the standard deviation of the data noise; The calculation expression of the number of LSTM layer units is: Where H is the number of units in each LSTM layer, C is a measure of data complexity, K is the limitation of computing resources, and α is a tuning parameter used to control the rate at which the number of units changes with complexity and resource limitations; The calculation expression of the dropout regularization rate is: Where D is the dropout regularization rate, which represents the ratio of dropout regularization, M is the number of samples in the data set, and β is a tuning parameter used to control the rate at which the dropout ratio changes with the size of the data set.
5. According to a network attack identification method based on the Snd-LSTM network model according to claim 4, it is characterized in that: In step 3, the training process of the Snd-LSTM network model is: Ensure that the network traffic data has been sorted in chronological order and generate sliding window time series data, and divide the data set into training set, validation set and test set, with a division ratio of 70% training set, 15% validation set and 15% test set; Assign a label of a specific attack type to each sample according to the multi-classification task type and compile the model, where the model compilation includes selecting a loss function, selecting an optimizer, and configuring evaluation indicators; Input the training set data into the Snd-LSTM network model, calculate the value of the loss function through forward propagation, calculate the gradient through the back-propagation algorithm, and use the optimization algorithm to update the model parameters. Repeat this process until the value of the loss function reaches the preset number of iterations, evaluate the performance of the model on the validation set, adjust the model parameters according to the validation results, retrain the model, and evaluate the performance of the final model on the test set; The trained Snd-LSTM network model is used to predict and analyze network traffic data and identify the dynamic change trend of abnormal behavior of network traffic.
6. According to claim 5, a network attack identification method based on the Snd-LSTM network model is characterized in that: The calculation expression of the dynamic change trend of the abnormal behavior is: Where A(t) is the quantitative value of the dynamic change trend of abnormal behavior at time t, and F i is the network traffic value at time i, μ is the average of recent traffic values, which is the mean within a sliding window, W is the sliding window size, thr is the preset abnormal behavior threshold, k is an adjustment parameter used to control the decay rate of abnormal values over time, ΔF(t) is the difference between the traffic value at time t and the traffic value at the previous moment, and the value range of A(t) is between 0 and 1.
7. A network attack identification method based on the Snd-LSTM network model according to claim 6, characterized in that: In step 4, the output process of the probability vector is: Collect real-time network traffic data from the network monitoring system and extract features including packet size, packet arrival interval, protocol type, source / destination IP address and port number; Load the trained Snd-LSTM model, make the loaded model compatible with the feature set extracted from real-time network traffic data, and input the preprocessed network traffic data into the model in batches; The forward propagation calculation is performed through the Snd-LSTM model. The Snd-LSTM model gradually calculates the hidden state based on the input features and the learned weights, and finally outputs a probability vector. Each element in the probability vector corresponds to a specific attack type.
8. A network attack identification method based on the Snd-LSTM network model according to claim 7, characterized in that: The calculation expression of the probability vector is: With j =min(θ ReLU(W j ·h T +b j ),δ); Where P j is the probability vector of the j-th attack, z j is the linear combination value before the fully connected layer and activation function, τ is the smoothing parameter, and h T is the hidden state vector of the LSTM unit at time step T, W j and b j are the weight matrix and bias vector of the fully connected layer, respectively, and θ is the scaling factor used to adjust z j The dynamic range of , δ is the upper limit.
9. A network attack identification method based on the Snd-LSTM network model according to claim 8, characterized in that: In step 5, the triggering process of the early warning mechanism is: According to the network attack warning requirements, combined with historical data, business requirements and security policies, the risk level of network attack types is analyzed and divided into low-risk attacks, medium-risk attacks and high-risk attacks. Different warning thresholds are set for each type of network attack. Normal traffic does not trigger warnings and there is no need to set warning thresholds. The warning threshold for low-risk attacks is 0.7, the warning threshold for medium-risk attacks is 0.85, and the warning threshold for high-risk attacks is 0.
95. Find the maximum probability value from the output probability vector and compare it with the warning threshold to determine whether the maximum probability value exceeds the preset warning threshold; If the maximum probability value does not exceed the warning threshold, it is regarded as normal traffic and no warning operation is performed. If the maximum probability value exceeds the warning threshold, it is determined to be a network attack and matched with the corresponding network attack type, thereby triggering the warning mechanism, which includes sending alarms, recording logs and blocking connections.
10. A network attack identification method based on the Snd-LSTM network model according to claim 9, characterized in that: In step 6, the process of forming the attack report is as follows: According to the output probability of the Snd-LSTM model and the preset warning threshold, the risk level of the attack event is determined, and corresponding emergency response measures are implemented according to the risk level. For high-risk network attack events, the automatic blocking mechanism is immediately activated. For medium-risk network attack events, the attacked traffic is diverted to the backup system or sandbox environment for analysis and processing. For all risk network attack events, real-time monitoring and log recording are required; After blocking the attack source, isolate the affected system components, start the recovery process, and reinforce the system and repair the vulnerabilities according to the attack type and means; After the attack is over, collect and analyze data from the entire attack process, including the attack source, attack means, attack path, and system response. Based on the results of the attack data analysis, write an attack report, including an overview of the attack, impact analysis, emergency response measures, security reinforcement recommendations, and future defense strategies. Then, optimize the network security strategy based on the recommendations in the attack report.
Citation Information
Patent Citations
Neural network time sequence classification method based on data enhancement
CN113035361A
Network multivariate time traffic sequence anomaly detection method and device based on multiple tasks
CN116401537A
Network security situation prediction method based on historical alarm event times
CN117319074A
Industrial Internet of Things network security situation prediction scheme based on linear gating future prediction network
CN119155086A
Communication behavior deep analysis and early warning method and device based on network flow data
CN119210844A
Cited By
DDoS attack defense method and system based on multi-source flow perception
CN120915548A